package fun.wlfj.servlet;

import java.io.IOException;
import javax.servlet.ServletException;
import javax.servlet.annotation.WebServlet;
import javax.servlet.http.HttpServlet;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

import fun.wlfj.factory.CashSystemFactory;
import fun.wlfj.vo.User;

/**
 * Servlet implementation class PayListInfoServlet
 */
@WebServlet("/PayListInfoServlet")
public class PayListInfoServlet extends HttpServlet {
	private static final long serialVersionUID = 1L;
       
    /**
     * @see HttpServlet#HttpServlet()
     */
    public PayListInfoServlet() {
        super();
        // TODO Auto-generated constructor stub
    }

	/**
	 * @see HttpServlet#doGet(HttpServletRequest request, HttpServletResponse response)
	 */
	protected void doGet(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		int PayListID = Integer.parseInt(request.getParameter("PayListID"));
		String from = request.getParameter("from");//这里有安全隐患
		User user = (User)request.getSession().getAttribute("User");
		if(request.getSession().getAttribute("FakeUser") != null) {
			user = new User();
			request.getSession().setAttribute("FakeUser", null);
		}
		if(user == null) {
			request.getRequestDispatcher("login.jsp").forward(request, response);
			return;
		}
		request.setAttribute("PayListInfo", CashSystemFactory.getPayListDao(user).getPayListByID(user.getUserID(), PayListID));
		request.getRequestDispatcher(from + ".jsp").forward(request, response);
	}

	/**
	 * @see HttpServlet#doPost(HttpServletRequest request, HttpServletResponse response)
	 */
	protected void doPost(HttpServletRequest request, HttpServletResponse response) throws ServletException, IOException {
		// TODO Auto-generated method stub
		doGet(request, response);
	}

}
